Zebrocy used heavily by the Sednit group over last two years
ID: 14508a67-5536-450a-bc1d-2d7ab05ec2b0
STIX ID: report--14508a67-5536-450a-bc1d-2d7ab05ec2b0
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2018-04-25
Last Modified Date: 2018-04-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET describes the Zebrocy malware family used by the Sednit (APT28/Fancy Bear) group: a multi-stage intrusion chain (Delphi downloader, AutoIt downloader, Delphi backdoor) delivered via malicious Office documents and archives that performs extensive reconnaissance and data collection and is used to deploy the Xagent backdoor on high-value targets (diplomats, embassies, ministries). The report documents evolving backdoor versions, TTPs, commands/capabilities, persistence mechanisms, and provides numerous IoCs (file hashes and C2 URLs) for detection and monitoring.
